Security

Trump’s cybersecurity executive order is a good first step

Comment

Image Credits: Andrew Harrer

Robert R. Ackerman Jr.

Contributor

Robert R. Ackerman Jr. is the founder and managing director of AllegisCyber, a venture capital firm specializing in cybersecurity, and the co-founder and executive at DataTribe, a cybersecurity startup foundry which focuses on launching startups based on cyber domain expertise from the intelligence community and national laboratories.

More posts from Robert R. Ackerman Jr.

A significant piece of cybersecurity news erupted last week, although it was nearly drowned out by the growing flap over President Trump’s firing of FBI Director James Comey.

There are two overriding points regarding President Trump’s executive order (EO) outlining plans to improve data security for federal agencies and to better protect critical U.S. infrastructure.

Firstly, this development was truly important — a serious call to action to beef up government cybersecurity measures at a time when breaches dominate the headlines and mounting worries about a future cyber war among nation-states are legitimate. Secondly, while this executive branch step was absolutely necessary, it is insufficient. We need to go much further.

The EO’s call for federal government agencies — especially civilian agencies — to seek opportunities to share cyber technology makes a great deal of sense.

Why reinvent the wheel, one government silo at a time? Eventually, this would spell disaster. And cloud-based computing and security frameworks available today make a holistic approach eminently possible.

Data security frameworks would then be layered atop the cloud framework so that data can be shared while also encrypted. Individual agencies could then build on this framework for any number of unique needs.

I know that government silos have varying degrees of expertise, resources and sophistication and are likely to embrace the counter-argument that they should largely remain silos. But security is only as strong as the weakest link in the network. If addressed, adversaries will find and exploit that link. In a large corporation, information technology requirements are not left to each function or department. Why should the government be different?

We need a mechanism in which cybersecurity experts in U.S. intelligence agencies could share some of their knowledge with U.S. industries, without disclosing too much information.

Experts at the forefront of coping with highly sophisticated cyber attacks at NSA and elsewhere need to be leveraged in the remedial process. This expertise could also be an element of a “cybersecurity infrastructure bank” — a bank that would loan government funds to small utilities, water plants and the like to help them quickly upgrade their cyber defenses.

We must recognize where most of the innovation in cyber actually takes place — in small, private cybersecurity startups — and take steps to help the government purchase technology and services from these companies.

The government today relies mostly on large, established cyber vendors and integrators, many of which do not sell state-of-the-art wares. The government must restructure procurement policies to attract more innovative blood into the game. Buying yesterday’s solution to defend against tomorrow’s challenges and threats is a waste of time and money — and does not make us more secure.

The government should cease buying cyber technology and related gear from foreign sources. As Russian and Chinese cyber attacks against the U.S., among others, help illustrate, it is simply too risky.

The government already does this to some extent, but it must do more. On the plus side, China-based Huawei Technologies, the world’s largest telecommunications equipment manufacturer, is banned from selling its gear in America, and for good reason. The company is reportedly controlled, in part, by China’s People Liberation Army. Now there is talk in Congress to ban Russian cybersecurity company Kaspersky Lab from doing business in the U.S.

The concern is logical. Trust is an absolute in vendor selection. Maybe Kaspersky hasn’t done anything wrong. But why not switch to a competitor anyway? We know Russia is engaging in nefarious activities, and there is evidence that Russia collaborates with private Russian security firms.

Last week, an incident at a Senate Intelligence Committee hearing said it all. The heads of six intelligence agencies, asked by Sen. Marco Rubio (R-Florida) whether they would be comfortable using Kaspersky software, all flatly said no. These agencies included the CIA, NSA and FBI.

U.S. infrastructure, including the electric grid, is much too vulnerable to cyber attack. The systems were designed to be functional, not necessarily secure, and that is clearly unacceptable.

A three-pronged strategy can begin fixing things. 1) The government should define a level of expected cyber resiliency and produce a methodology to protect it. 2) We should create a clearing center for the implementation of best practices in grid security. 3) We should form an industrial bank to provide long-term financing to utilities that need it in order to help implement this.

We must deal with the reality that many smaller utilities today have neither the financial nor technical resources to become secure.

President Trump’s EO sets a 90-day deadline for each agency in the executive branch to submit a risk management report. It would describe their security measures and what are deemed to be significant risks. It also requests a study to determine whether at least some agencies can realistically adopt consolidated network architectures.

Ninety days brings us to late summer. Let’s hope meaningful progress is made by then — and that the disseminated reports are secured, not a visible roadmap to our vulnerabilities. A major overall fix is still years away. But you have to start somewhere. As Mark Twain once wrote, “The secret to getting ahead is getting started.

More TechCrunch

On the heels of raising $102 million earlier this year, Bugcrowd is making good on its promise to use some of that funding to make acquisitions to strengthen its security…

Bugcrowd, the crowdsourced white-hat hacker platform, acquires Informer to ramp up its security chops

Google is preparing to build what will be the first subsea fibre optic cable connecting the continents of Africa and Australia. The news comes as the major cloud hyperscalers battle…

Google to build first subsea fibre optic cable connecting Africa with Australia

The Kia EV3 — the new all-electric compact SUV revealed Thursday — illustrates a growing appetite among global automakers to bring generative AI into their vehicles.  The automaker said the…

The new Kia EV3 will have an AI assistant with ChatGPT DNA

Bing, Microsoft’s search engine, isn’t working properly right now. At first, we noticed it wasn’t possible to perform a web search at all. Now it seems search results are loading…

Bing’s API is down, taking Microsoft Copilot, DuckDuckGo and ChatGPT’s web search feature down too

If you thought autonomous driving was just for cars, think again. The so-called ‘autonomous navigation’ market — where ships steer themselves guided by AI, resulting in fuel and time savings…

Autonomous shipping startup Orca AI tops up with $23M led by OCV Partners and MizMaa Ventures

The best known mycoprotein is probably Quorn, a meat substitute that’s fast approaching its 40th birthday. But Finnish biotech startup Enifer is cooking up something even older: Its proprietary single-cell…

Meet the Finnish biotech startup bringing a long lost mycoprotein to your plate

Silo, a Bay Area food supply chain startup, has hit a rough patch. TechCrunch has learned that the company on Tuesday laid off roughly 30% of its staff, or north…

Food supply chain software maker Silo lays off ~30% of staff amid M&A discussions

Featured Article

Meta’s new AI council is composed entirely of white men

Meanwhile, women and people of color are disproportionately impacted by irresponsible AI.

14 hours ago
Meta’s new AI council is composed entirely of white men

If you’ve ever wanted to apply to Y Combinator, here’s some inside scoop on how the iconic accelerator goes about choosing companies.

Garry Tan has revealed his ‘secret sauce’ for getting into Y Combinator

Indian ride-hailing startup BluSmart has started operating in Dubai, TechCrunch has exclusively learned and confirmed with its executive. The move to Dubai, which has been rumored for months, could help…

India’s BluSmart is testing its ride-hailing service in Dubai

Under the envisioned framework, both candidate and issue ads would be required to include an on-air and filed disclosure that AI-generated content was used.

FCC proposes all AI-generated content in political ads must be disclosed

Want to make a founder’s day, week, month, and possibly career? Refer them to Startup Battlefield 200 at Disrupt 2024! Applications close June 10 at 11:59 p.m. PT. TechCrunch’s Startup…

Refer a founder to Startup Battlefield 200 at Disrupt 2024

Social networking startup and X competitor Bluesky is officially launching DMs (direct messages), the company announced on Wednesday. Later, Bluesky plans to “fully support end-to-end encrypted messaging down the line,”…

Bluesky now has DMs

The perception in Silicon Valley is that every investor would love to be in business with Peter Thiel. But the venture capital fundraising environment has become so difficult that even…

Peter Thiel-founded Valar Ventures raised a $300 million fund, half the size of its last one

Featured Article

Spyware found on US hotel check-in computers

Several hotel check-in computers are running a remote access app, which is leaking screenshots of guest information to the internet.

18 hours ago
Spyware found on US hotel check-in computers

Gavet has had a rocky tenure at Techstars and her leadership was the subject of much controversy.

Techstars CEO Maëlle Gavet is out

The struggle isn’t universal, however.

Connected fitness is adrift post-pandemic

Featured Article

A comprehensive list of 2024 tech layoffs

The tech layoff wave is still going strong in 2024. Following significant workforce reductions in 2022 and 2023, this year has already seen 60,000 job cuts across 254 companies, according to independent layoffs tracker Layoffs.fyi. Companies like Tesla, Amazon, Google, TikTok, Snap and Microsoft have conducted sizable layoffs in the first months of 2024. Smaller-sized…

19 hours ago
A comprehensive list of 2024 tech layoffs

HoundDog actually looks at the code a developer is writing, using both traditional pattern matching and large language models to find potential issues.

HoundDog.ai helps developers prevent personal information from leaking

The changes are designed to enhance the consumer experience of using Google Pay and make it a more competitive option against other payment methods.

Google Pay will now display card perks, BNPL options and more

Few figures in the tech industry have earned the storied reputation of Vinod Khosla, founder and partner at Khosla Ventures. For over 40 years, he has been at the center…

Vinod Khosla is coming to Disrupt to discuss how AI might change the future

AI has already started replacing voice agents’ jobs. Now, companies are exploring ways to replace the existing computer-generated voice models with synthetic versions of human voices. Truecaller, the widely known…

Truecaller partners with Microsoft to let its AI respond to calls in your own voice

Meta is updating its Ray-Ban smart glasses with new hands-free functionality, the company announced on Wednesday. Most notably, users can now share an image from their smart glasses directly to…

Meta’s Ray-Ban smart glasses now let you share images directly to your Instagram Story

Spotify launched its own font, the company announced on Wednesday. The music streaming service hopes that its new typeface, “Spotify Mix,” will help Spotify distinguish its own unique visual identity. …

Why Spotify is launching its own font, Spotify Mix

In 2008, Marty Kagan, who’d previously worked at Cisco and Akamai, co-founded Cedexis, a (now-Cisco-owned) firm developing observability tech for content delivery networks. Fellow Cisco veteran Hasan Alayli joined Kagan…

Hydrolix seeks to make storing log data faster and cheaper

A dodgy email containing a link that looks “legit” but is actually malicious remains one of the most dangerous, yet successful, tricks in a cybercriminal’s handbook. Now, an AI startup…

Bolster, creator of the CheckPhish phishing tracker, raises $14M led by Microsoft’s M12

If you’ve been looking forward to seeing Boeing’s Starliner capsule carry two astronauts to the International Space Station for the first time, you’ll have to wait a bit longer. The…

Boeing, NASA indefinitely delay crewed Starliner launch

TikTok is the latest tech company to incorporate generative AI into its ads business, as the company announced on Tuesday that it’s launching a new “TikTok Symphony” AI suite for…

TikTok turns to generative AI to boost its ads business

Gone are the days when space and defense were considered fundamentally antithetical to venture investment. Now, the country’s largest venture capital firms are throwing larger portions of their money behind…

Space VC closes $20M Fund II to back frontier tech founders from day zero